CVE-2026-47412: CWE-269: Improper Privilege Management in MervinPraison praisonai-platform
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including every project, issue, comment, agent, label, and member record (cascading via the foreign-key relationships). There is no owner-role gate, no confirmation token, no soft-delete window, no recovery path. PraisonAI Platform version 0.1.4 patches the issue.
AI Analysis
Technical Summary
The PraisonAI Platform's DELETE /workspaces/{workspace_id} endpoint is protected only by a minimal role check requiring membership in the workspace. This insufficient privilege management (CWE-269) enables any member to perform destructive deletion of the entire workspace, including projects, issues, comments, agents, labels, and member records, with no owner-level gate, confirmation token, or recovery mechanism. Versions prior to 0.1.4 are affected. The vulnerability is classified under CWE-269 (Improper Privilege Management) and CWE-862 (Missing Authorization).
Potential Impact
An attacker with member-level access to a workspace can irreversibly delete the entire workspace and all its contents, causing high impact on data integrity and availability. There is no recovery or soft-delete mechanism, resulting in permanent data loss. Confidentiality is not directly impacted, but the destruction of data severely affects operational continuity.
Mitigation Recommendations
Upgrade PraisonAI Platform to version 0.1.4 or later, where this authorization bypass vulnerability is patched. Prior to upgrading, restrict workspace membership to trusted users only. No other official remediation or temporary fix is documented. Patch status is not explicitly confirmed in vendor advisory, but version 0.1.4 is stated as the fixed release.
CVE-2026-47412: CWE-269: Improper Privilege Management in MervinPraison praisonai-platform
Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including every project, issue, comment, agent, label, and member record (cascading via the foreign-key relationships). There is no owner-role gate, no confirmation token, no soft-delete window, no recovery path. PraisonAI Platform version 0.1.4 patches the issue.
CVSS v3.1
Score 8.1high
Affected software
pkg:github/mervinpraison/praisonai-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PraisonAI Platform's DELETE /workspaces/{workspace_id} endpoint is protected only by a minimal role check requiring membership in the workspace. This insufficient privilege management (CWE-269) enables any member to perform destructive deletion of the entire workspace, including projects, issues, comments, agents, labels, and member records, with no owner-level gate, confirmation token, or recovery mechanism. Versions prior to 0.1.4 are affected. The vulnerability is classified under CWE-269 (Improper Privilege Management) and CWE-862 (Missing Authorization).
Potential Impact
An attacker with member-level access to a workspace can irreversibly delete the entire workspace and all its contents, causing high impact on data integrity and availability. There is no recovery or soft-delete mechanism, resulting in permanent data loss. Confidentiality is not directly impacted, but the destruction of data severely affects operational continuity.
Mitigation Recommendations
Upgrade PraisonAI Platform to version 0.1.4 or later, where this authorization bypass vulnerability is patched. Prior to upgrading, restrict workspace membership to trusted users only. No other official remediation or temporary fix is documented. Patch status is not explicitly confirmed in vendor advisory, but version 0.1.4 is stated as the fixed release.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T19:37:43.525Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5faf7c2a4a8d59898322b2
Added to database: 07/21/2026, 17:42:20 UTC
Last enriched: 07/21/2026, 17:57:26 UTC
Last updated: 07/21/2026, 21:11:24 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.